Privacy Policy

    Your Privacy is Our Priority

    We are committed to protecting your personal information and being transparent about how we collect, use, and safeguard your data in compliance with Canadian privacy laws.

    Effective Date: October 25, 2025

    Last Updated: October 25, 2025

    Version: 2.0

    Legal Entity: AssetLab CMMS Software Inc., North Vancouver, British Columbia, Canada

    Multi-Jurisdictional Compliance: This Privacy Policy is designed to comply with:

    • Canada's Personal Information Protection and Electronic Documents Act (PIPEDA)
    • European Union General Data Protection Regulation (GDPR)
    • California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA)
    • Canada's Anti-Spam Legislation (CASL)

    1. Introduction

    1.1 Scope and Application

    AssetLab CMMS Software Inc. ("AssetLab," "we," "us," or "our") respects your privacy and is committed to protecting your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our asset management platform and services (the "Service").

    This Privacy Policy applies to all users of AssetLab, including visitors to our website (assetlab.ca), registered users of the Service, and individuals whose information is processed through the Service. This Policy should be read in conjunction with our Terms of Service, which govern your use of the Service.

    1.2 Data Controller and Data Processor Roles

    For purposes of applicable data protection laws:

    • AssetLab as Data Controller: For information we collect directly from you (account information, billing data, website usage), AssetLab acts as the "Data Controller" or "Business," determining the purposes and means of processing.
    • AssetLab as Data Processor: For Customer Data you upload to the Service, AssetLab acts as a "Data Processor" or "Service Provider," processing personal information solely on your behalf and according to your instructions. In this role, you (our customer) are the Data Controller responsible for obtaining necessary consents and ensuring lawful processing.

    This dual-role structure is further detailed in our Terms of Service (Section 8: Data Protection, Privacy, and Processing).

    1.3 Consent and Acceptance

    By accessing or using the Service, you consent to the collection, use, and disclosure of your information as described in this Privacy Policy. If you do not agree with our policies and practices, you must not access or use the Service.

    Where we require your consent for specific processing activities (e.g., marketing communications, optional cookies), we will seek your explicit opt-in consent at the time of collection.

    2. Information We Collect

    We collect several types of information from and about users of our Service:

    2.1 Personal Information

    Personal information is data that can be used to identify you. We collect the following types of personal information:

    • Account Information: Name, email address, phone number, job title, organization name
    • Authentication Data: Email address for OTP (one-time password) authentication via Clerk
    • Billing Information: Payment method details (processed securely by third-party payment processors)
    • Profile Information: User preferences, settings, and profile customization
    • Communication Data: Information you provide when contacting our support team or communicating with us

    2.2 Customer Data

    Customer Data is information you input, upload, or create while using the Service, including:

    • Asset information (descriptions, locations, specifications, serial numbers)
    • Work order details and maintenance records
    • Vendor and contractor information
    • Parts inventory and procurement data
    • Financial data related to asset management (costs, budgets, expenses)
    • Documents, images, and attachments uploaded to the platform
    • Any other business data you choose to store in the Service

    Important: You retain all ownership rights to your Customer Data. We process Customer Data only as necessary to provide the Service and as instructed by you.

    2.3 Automatically Collected Information

    When you access or use the Service, we automatically collect certain technical information:

    • Usage Data: Pages visited, features used, time spent on pages, click patterns
    • Device Information: Device type, operating system, browser type and version
    • Log Data: IP address, access times, error logs, performance data
    • Cookies and Similar Technologies: Session identifiers, preferences, authentication tokens

    2.4 Information from Third Parties

    We may receive information about you from third-party services:

    • Clerk: Authentication and identity verification data
    • Payment Processors: Payment confirmation and billing information
    • Analytics Services: Aggregated usage statistics and performance metrics

    3. How We Use Your Information

    We use the information we collect for the following purposes:

    3.1 Service Delivery

    • Create and manage your account
    • Authenticate your identity and maintain security
    • Provide access to the Service and its features
    • Process and store your Customer Data
    • Deliver customer support and respond to inquiries

    3.2 Billing and Payments

    • Process subscription fees and payments
    • Generate invoices and billing statements
    • Manage subscription renewals and cancellations
    • Detect and prevent payment fraud

    3.3 Communication

    • Send transactional emails (account notifications, password resets, billing confirmations)
    • Provide customer support and technical assistance
    • Send service announcements and updates (with opt-out option for non-essential communications)
    • Respond to your requests, questions, and feedback

    3.4 Service Improvement and Analytics

    • Monitor and analyze usage patterns to improve the Service
    • Develop new features and functionality
    • Conduct research and analytics (using aggregated, anonymized data)
    • Troubleshoot technical issues and optimize performance

    3.5 Security and Compliance

    • Detect, prevent, and respond to fraud, abuse, and security incidents
    • Enforce our Terms of Service and other policies
    • Comply with legal obligations and regulatory requirements
    • Protect the rights, property, and safety of AssetLab, our users, and others

    4. Legal Basis for Processing (PIPEDA Compliance)

    Under PIPEDA, we process personal information based on the following legal grounds:

    • Consent: You provide explicit or implied consent when creating an account and using the Service
    • Contract Performance: Processing is necessary to fulfill our contractual obligations under the Terms of Service
    • Legal Obligations: Processing is required to comply with Canadian laws and regulations
    • Legitimate Interests: Processing is necessary for our legitimate business interests (e.g., fraud prevention, service improvement) that do not override your privacy rights

    5. How We Share Your Information

    We do not sell, rent, or trade your personal information. We may share your information in the following limited circumstances:

    5.1 Service Providers (Subprocessors)

    We engage trusted third-party service providers to assist in operating the Service:

    • Clerk: Authentication and user identity management (SOC 2 Type II certified)
    • Supabase: Database hosting and infrastructure (SOC 2 Type II certified, Canadian data residency)
    • Payment Processors: Secure payment processing (PCI-DSS compliant)
    • Email Service Providers: Transactional email delivery

    All service providers are contractually obligated to protect your information and use it only for the purposes we specify.

    5.2 Legal Requirements

    We may disclose your information if required to do so by law or in response to:

    • Valid legal processes (subpoenas, court orders, search warrants)
    • Requests from government authorities or law enforcement
    • Compliance with applicable laws and regulations
    • Protection of our legal rights or those of others

    5.3 Business Transfers

    In the event of a merger, acquisition, reorganization, or sale of assets, your information may be transferred to the successor entity. We will provide notice before your information is transferred and becomes subject to a different privacy policy.

    5.4 With Your Consent

    We may share your information for other purposes with your explicit consent.

    6. Data Security

    We implement industry-standard security measures to protect your information:

    6.1 Technical Safeguards

    • Encryption: TLS 1.3 for data in transit, AES-256 for data at rest
    • Authentication: Passwordless OTP authentication via Clerk with optional MFA
    • Access Controls: Role-based access control (RBAC) with 173 granular permissions
    • Database Security: PostgreSQL row-level security (RLS) for multi-tenant data isolation
    • Network Security: Firewalls, intrusion detection, and DDoS protection

    6.2 Organizational Safeguards

    • Regular security training for employees
    • Strict internal access policies (need-to-know basis)
    • Third-party security audits and penetration testing
    • Incident response and breach notification procedures
    • Background checks for employees with access to sensitive data

    6.3 Security Limitations

    While we implement strong security measures, no system is completely secure. We cannot guarantee absolute security of your information. You are responsible for maintaining the confidentiality of your account credentials and for any activities under your account.

    6.4 Data Breach Notification and Incident Response

    Data Breach Protocol: In the event of a security incident that results in unauthorized access to, disclosure of, or loss of personal information, AssetLab has established the following notification protocol in compliance with PIPEDA, GDPR, and applicable provincial laws.

    Notification Timeline and Process

    If we determine that a data breach has occurred that poses a real risk of significant harm to affected individuals, we will:

    • Notify Affected Users: Within 72 hours of becoming aware of the breach (GDPR Article 34 compliance), or as soon as feasible under PIPEDA, we will notify affected individuals via email to the address associated with their account
    • Notify Regulatory Authorities: Report the breach to the Office of the Privacy Commissioner of Canada (OPC), relevant provincial authorities, and/or EU supervisory authorities within required timelines
    • Notify Our Customers (B2B): If Customer Data is affected, we will immediately notify the relevant customer organization to enable them to fulfill their own notification obligations under applicable data protection laws

    Information Provided in Breach Notifications

    Our breach notifications will include:

    • A description of the nature and extent of the breach, including categories and approximate number of affected individuals and data records
    • The likely consequences of the breach and potential risks to affected individuals
    • Measures taken or proposed to address the breach, mitigate harm, and prevent future incidents
    • Contact information for our Privacy Officer and instructions for individuals to protect themselves (e.g., password resets, fraud monitoring)
    • Information about your right to lodge a complaint with supervisory authorities

    Incident Response Measures

    Upon detecting a security incident, AssetLab will immediately:

    • Contain and remediate the breach to prevent further unauthorized access
    • Conduct a thorough investigation to determine the scope, cause, and impact
    • Preserve evidence for forensic analysis and regulatory investigations
    • Implement additional security measures to prevent recurrence
    • Provide regular updates to affected individuals throughout the response process

    Your Rights Following a Breach

    If your personal information is affected by a data breach, you have the right to:

    • Receive timely and transparent information about the breach
    • Request deletion of your compromised personal information
    • File a complaint with the Office of the Privacy Commissioner of Canada or relevant supervisory authority
    • Seek compensation for damages resulting from the breach, subject to applicable law and our Terms of Service (Section 10: Limitation of Liability)

    7. Data Retention

    We retain your information for as long as necessary to fulfill the purposes outlined in this Privacy Policy:

    • Active Accounts: Personal information and Customer Data are retained for the duration of your active subscription
    • Terminated Accounts: After account termination, we retain data for 30 days to allow for reactivation or data recovery
    • Backup Data: Deleted data may persist in backups for up to 90 days before permanent deletion
    • Legal Compliance: We may retain certain data longer if required by law (e.g., tax records for 7 years)
    • Anonymized Data: We may retain aggregated, anonymized data indefinitely for analytics and research

    8. Your Privacy Rights (PIPEDA)

    Under Canada's Personal Information Protection and Electronic Documents Act (PIPEDA), you have the following rights:

    8.1 Right to Access

    You have the right to request a copy of all personal information we hold about you. We will provide this information within 30 days of your request, subject to verification of your identity.

    8.2 Right to Correction

    You have the right to request corrections to any inaccurate or incomplete personal information. You can update most information directly in your account settings.

    8.3 Right to Deletion

    You have the right to request deletion of your personal information and Customer Data, subject to:

    • Legal obligations requiring us to retain certain data
    • Legitimate business purposes (e.g., fraud prevention, resolving disputes)
    • Backup retention periods (up to 90 days)

    8.4 Right to Data Portability

    You have the right to export your Customer Data in commonly used formats (CSV, JSON) at any time through the Service interface.

    8.5 Right to Withdraw Consent

    You may withdraw your consent to our processing of your personal information at any time by terminating your account. Note that withdrawal of consent may prevent us from providing the Service.

    8.6 Right to File a Complaint

    If you believe we have not complied with PIPEDA, you have the right to file a complaint with the Office of the Privacy Commissioner of Canada (OPC).

    8.7 Exercising Your Rights

    To exercise any of these rights, please contact us at privacy@assetlab.ca. We will respond to your request within 30 days.

    9. Sensitive Personal Information We Do NOT Collect

    IMPORTANT: AssetLab is NOT designed to collect, store, or process sensitive personal information. You are PROHIBITED from uploading the following types of data to the Service, as specified in our Terms of Service (Section 6.2: Prohibited Data Types).

    Prohibited Data Categories

    The following categories of sensitive personal information must NOT be uploaded to or stored in the Service:

    • Government-Issued Identifiers: Social Insurance Numbers (SINs), Social Security Numbers (SSNs), passport numbers, driver's license numbers, national identification numbers
    • Financial Account Information: Credit/debit card numbers, bank account numbers, financial credentials (except as processed by our PCI-DSS compliant payment processor Stripe for billing purposes only)
    • Protected Health Information (PHI): Medical records, health insurance information, diagnoses, treatment information, or any data subject to HIPAA, PHIPA, or similar health privacy laws
    • Biometric Data: Fingerprints, facial recognition data, retinal scans, voiceprints, DNA, or other biometric identifiers
    • Sensitive Personal Characteristics: Data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, sex life, or sexual orientation
    • Children's Personal Information: Personal information of individuals under age 13 (or applicable age of digital consent in your jurisdiction - 16 in the EU)
    • Criminal Records: Information about criminal convictions, offenses, or related security measures
    • Authentication Credentials for Third-Party Systems: Passwords, API keys, access tokens, or cryptographic private keys for external systems

    Consequences of Uploading Prohibited Data

    If you upload prohibited sensitive data to the Service:

    • You are in material breach of our Terms of Service
    • AssetLab may immediately suspend or terminate your account without refund
    • You are solely responsible for any regulatory penalties, fines, or third-party claims arising from such unauthorized data uploads
    • You indemnify AssetLab for all costs and damages resulting from your upload of prohibited data (see Terms of Service Section 11: Indemnification)

    10. Your California Privacy Rights (CCPA/CPRA)

    California Residents: If you are a California resident, the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA) provide you with additional rights regarding your personal information.

    10.1 Categories of Personal Information Collected

    In the preceding 12 months, AssetLab has collected the following categories of personal information from California residents:

    • Identifiers: Name, email address, IP address, unique device identifiers
    • Commercial Information: Purchase history, subscription plan, transaction records
    • Internet/Network Activity: Browsing history on our website, usage data, log files
    • Professional/Employment Information: Job title, company name, work contact information
    • Inferences: Preferences, usage patterns, and characteristics derived from your activity

    10.2 Do Not Sell or Share My Personal Information

    We Do NOT Sell Your Personal Information: AssetLab does not sell, and has not sold in the preceding 12 months, personal information of California residents to third parties for monetary or other valuable consideration.

    We do not "share" personal information for cross-context behavioral advertising purposes as defined by the CPRA. We do not engage in targeted advertising or profiling in furtherance of decisions that produce legal or similarly significant effects.

    10.3 Your CCPA/CPRA Rights

    California residents have the following rights:

    • Right to Know: Request disclosure of the categories and specific pieces of personal information we have collected about you, the sources from which it was collected, the purposes for collection, and the categories of third parties with whom we share it
    • Right to Delete: Request deletion of your personal information, subject to certain exceptions (e.g., legal compliance, fraud prevention)
    • Right to Correct: Request correction of inaccurate personal information we maintain about you
    • Right to Opt-Out of Sale/Sharing: Opt-out of the sale or sharing of your personal information (note: we do not sell or share as defined by CCPA/CPRA)
    • Right to Limit Use of Sensitive Personal Information: Limit our use of sensitive personal information (note: we do not collect sensitive personal information as defined by CPRA)
    • Right to Non-Discrimination: You will not receive discriminatory treatment for exercising your CCPA/CPRA rights

    10.4 Exercising Your CCPA/CPRA Rights

    To exercise your rights under CCPA/CPRA, please:

    • Email us at privacy@assetlab.ca with the subject line "CCPA Request"
    • Submit a request through your account settings (for registered users)

    We will verify your identity before processing your request and respond within 45 days (extendable by an additional 45 days if reasonably necessary). You may designate an authorized agent to make a request on your behalf by providing written authorization.

    10.5 Shine the Light Law

    California Civil Code Section 1798.83 permits California residents to request information about our disclosure of personal information to third parties for their direct marketing purposes. AssetLab does not disclose personal information to third parties for their direct marketing purposes.

    11. Automated Decision-Making and Profiling

    11.1 No Automated Decision-Making with Legal Effects

    AssetLab does not engage in automated decision-making (including profiling) that produces legal effects concerning you or similarly significantly affects you, as defined by GDPR Article 22.

    Specifically, we do not use automated processing to make decisions about:

    • Your eligibility for the Service
    • Credit decisions, insurance underwriting, or similar financial assessments
    • Employment decisions, performance evaluations, or disciplinary actions
    • Legal rights, contractual obligations, or access to essential services

    11.2 Analytics and Service Optimization

    We do use automated processing for the following purposes, which do not produce legal or similarly significant effects:

    • Usage Analytics: Analyzing usage patterns to improve Service performance and user experience
    • Security Monitoring: Detecting fraudulent or abusive activity through automated threat detection systems
    • Service Personalization: Customizing your user interface based on preferences and past activity (e.g., recently accessed assets, saved views)
    • Feature Recommendations: Suggesting Service features that may be useful based on your subscription tier and usage patterns

    You may opt-out of non-essential analytics and personalization through your account settings.

    11.3 Future AI Features (If Implemented)

    If we introduce AI-powered features in the future (e.g., predictive maintenance recommendations, automated work order prioritization), we will:

    • Clearly disclose the use of automated decision-making or profiling
    • Provide information about the logic involved and the significance of such processing
    • Obtain your explicit consent where required by law
    • Provide mechanisms to challenge automated decisions and request human review
    • Comply with all applicable AI governance frameworks and regulations

    See our Terms of Service (Section 15: Artificial Intelligence Features) for additional information about AI-related terms.

    12. Marketing Communications and Opt-Out

    12.1 Types of Communications

    AssetLab may send you the following types of communications:

    • Transactional Communications (Cannot Opt-Out): Account notifications, password resets, billing confirmations, security alerts, Service updates required for platform functionality
    • Service Announcements (Can Opt-Out): New feature releases, product updates, maintenance notifications, best practices guides
    • Marketing Communications (Opt-In Required): Promotional emails, newsletters, webinar invitations, case studies, industry insights

    12.2 CASL Compliance (Canada's Anti-Spam Legislation)

    AssetLab complies with Canada's Anti-Spam Legislation (CASL). We will only send you commercial electronic messages (CEMs) if:

    • You have provided express consent by opting in to receive marketing communications
    • We have an existing business relationship with you (e.g., you are an active subscriber), and the message relates to your use of the Service
    • You have inquired about the Service within the past 6 months, and the message relates to your inquiry

    12.3 How to Opt-Out of Marketing Communications

    You may opt-out of marketing communications at any time by:

    • Clicking the "Unsubscribe" link in any marketing email
    • Updating your email preferences in your account settings
    • Emailing privacy@assetlab.ca with the subject line "Unsubscribe"
    • Replying to any marketing email with "STOP" or "UNSUBSCRIBE"

    We will process your opt-out request within 10 business days as required by CASL. Note that opting out of marketing communications will not affect transactional communications necessary for Service operation.

    12.4 Do Not Track Signals

    Some web browsers have a "Do Not Track" (DNT) feature that signals to websites that you do not want to have your online activity tracked. Currently, there is no universally accepted standard for how to respond to DNT signals. As a result, AssetLab does not respond to DNT browser signals. However, you can manage cookies and tracking through your browser settings and our cookie preferences center.

    13. Data Location and Cross-Border Transfers

    13.1 Canadian Data Residency

    All personal information and Customer Data is stored on servers located in Canada (AWS ca-central-1 region via Supabase). Your data does not leave Canada without your explicit consent.

    13.2 Service Providers

    Some of our service providers (e.g., Clerk for authentication) may process data outside of Canada. When this occurs:

    • We ensure adequate contractual protections are in place
    • Service providers comply with SOC 2 Type II or equivalent security standards
    • Data processing is limited to what is necessary to provide the Service

    14. Cookies and Tracking Technologies

    We use cookies and similar technologies to provide, secure, and improve the Service:

    14.1 Essential Cookies

    Required for the Service to function (authentication, session management, security). These cannot be disabled.

    14.2 Functional Cookies

    Remember your preferences and settings to enhance your experience.

    14.3 Analytics Cookies

    Help us understand how users interact with the Service to improve functionality and performance. These are optional and can be disabled in your browser settings.

    15. Children's Privacy

    The Service is not intended for individuals under the age of 18. We do not knowingly collect personal information from children. If you believe we have collected information from a child, please contact us immediately at privacy@assetlab.ca and we will delete the information.

    16. Changes to This Privacy Policy

    We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. We will notify you of material changes by:

    • Posting the updated Privacy Policy on our website with a new "Last Updated" date
    • Sending an email notification to your registered email address
    • Displaying an in-app notification upon your next login

    Material changes will be effective 30 days after notice is provided. Your continued use of the Service after the effective date constitutes acceptance of the updated Privacy Policy.

    17. Contact Information

    If you have questions, concerns, or requests regarding this Privacy Policy or our privacy practices, please contact us:

    AssetLab CMMS Software Inc.

    Privacy Officer: privacy@assetlab.ca

    General Inquiries: support@assetlab.ca

    Address: North Vancouver, British Columbia, Canada

    Response Time: We will respond to privacy requests within 30 days

    Office of the Privacy Commissioner of Canada

    If you are not satisfied with our response to your privacy concerns, you may contact the Office of the Privacy Commissioner of Canada:

    Website: www.priv.gc.ca

    Toll-Free: 1-800-282-1376

    Email: info@priv.gc.ca

    Legal Notice: This Privacy Policy was last updated on October 25, 2025 (Version 2.0). We strongly recommend printing or saving a copy of this Policy for your records.

    Key Enhancements in Version 2.0: This updated Privacy Policy includes comprehensive PIPEDA/GDPR/CCPA compliance, 72-hour data breach notification protocol (Section 6.4), explicit sensitive data prohibitions (Section 9), California Consumer Privacy Rights with "Do Not Sell" confirmation (Section 10), automated decision-making disclosures (Section 11), CASL-compliant marketing opt-out mechanisms (Section 12), data controller/processor role definitions (Section 1.2), and cross-references to our Terms of Service. These enhancements ensure AssetLab meets the highest standards of privacy protection across multiple jurisdictions.

    Your Privacy Matters: We are committed to transparency, accountability, and user control in all our privacy practices. If you have any questions or concerns about how we handle your personal information, please don't hesitate to contact our Privacy Officer at privacy@assetlab.ca.

    We Value Your Privacy

    We use cookies to provide essential functionality and optional analytics to improve your experience. Analytics cookies help us understand how you use AssetLab so we can make it better. Learn more in our Privacy Policy.